Open pintomi1989 opened 2 months ago
I wonder if we could set up Fleet => AWS Firehose => Microsoft Sentinel.
Hey @dherder have we set up something like this for any other customers?
If not, is it doable?
cc @pintomi1989
@noahtalerman i don't see why a standard data stream like kinesis wouldn't be consumable by Sentinel. Maybe this: https://samilamppu.com/2022/01/17/microsoft-sentinel-how-to-leverage-built-in-amazon-web-services-s3-data-connector/ would help?
FYI @pintomi1989 ^^
Sounds like we can use one of Fleet's log destinations to pipe data to Microsoft Sentinel.
As a Fleet user, I would like to see a native integration between Fleet and Sentinel as a logging destination. A one pane of glass or easy in UI setup would be optimal.